Executive brief
Oracle Mobile Application Server is a core component of Oracle E-Business Suite that handles mobile application traffic and terminal server communications. An unauthenticated attacker with physical access to the network segment where the server resides can exploit a difficult-to-exploit vulnerability to take complete control of the server, potentially compromising sensitive business data and disrupting operations across the entire E-Business Suite environment.
Technical details
The vulnerability exists in the MWA Terminal Server component of Oracle Mobile Application Server and allows unauthenticated remote code execution or system compromise. The attack requires adjacent network access (physical proximity to the communication segment) but no authentication credentials or user interaction, making it accessible to network-adjacent attackers. The difficulty of exploitation is elevated by unspecified complexity factors (AC:H), but successful exploitation results in complete system takeover with high impact to confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle E-Business Suite's Mobile Application Server.
Affected products
- Oracle Mobile Application Server 12.2.3 to 12.2.15
Timeline
- 2026-09-15: disclosed